CVE-2026-8989: Open Recovery Mode
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Do not allow the hardware recovery pins to put the NXP i.MX6 into recovery mode; prevent access to the recovery pins so an attacker with physical access cannot enter the i.MX6 recovery mode ("Open Recovery Mode").
Autel Maxi Charger Single Recovery mode (NXP i.MX6) via exposed hardware recovery pins = Enable/Unrestricted access should be prevented
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8989?
The severity of CVE-2026-8989 is high, with a score of 8.6 on the CVSS scale.
How do I fix CVE-2026-8989?
To mitigate CVE-2026-8989, restrict physical access to the device and ensure firmware is updated to the latest secure version.
What type of access does CVE-2026-8989 allow?
CVE-2026-8989 allows unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins.
Who is affected by CVE-2026-8989?
CVE-2026-8989 affects users of Autel Maxi Charger Single firmware prior to version V1.03.51.
What are the potential risks associated with CVE-2026-8989?
The potential risks include modification or extraction of firmware and sensitive data by an attacker with physical access.